MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 fb3292555a7607f5861b24d8e766257f9990644a06cd2eaefb4075357d8ef386. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Formbook
Vendor detections: 6
| SHA256 hash: | fb3292555a7607f5861b24d8e766257f9990644a06cd2eaefb4075357d8ef386 |
|---|---|
| SHA3-384 hash: | bb12f536f12a6fc30fb11085addefc5be7e0c32af813c72ac18c102b15f3991801f99b1e19e796f58b48332d13196884 |
| SHA1 hash: | bc62bd119cd2f57590664ae237ac4bef569fff61 |
| MD5 hash: | 06eafdaa87cc5c8f16a9540febc9ef74 |
| humanhash: | spaghetti-robert-juliet-louisiana |
| File name: | DOC982761717.DOC.zip |
| Download: | download sample |
| Signature | Formbook |
| File size: | 523'144 bytes |
| First seen: | 2022-03-01 08:19:08 UTC |
| Last seen: | Never |
| File type: | zip |
| MIME type: | application/zip |
| ssdeep | 12288:rlm87WAskGJLIfn0Iu+45OMUQoh8ZHuXg+r9AHZcHsIu:rll7p/GJL0qqMUvkgyHZVIu |
| TLSH | T1D8B423E09642CE43CB355CB75B423F4DEDF1BD6A06B3899C69B859B0001EF41C2DA98B |
| Reporter | |
| Tags: | FormBook zip |
cocaman
Malicious email (T1566.001)From: "info@cordeel.bg" (likely spoofed)
Received: "from ws01.fastweb.ro (unknown [193.169.145.11]) "
Date: "Mon, 28 Feb 2022 07:52:00 +0100"
Subject: "=?UTF-8?Q?RE=3A_=5BEXTERNAL=5D_RE=3A_=D0=9D=D0=BE=D0=B2=D0=B0_?=
=?UTF-8?Q?=D0=BF=D0=BE=D1=80=D1=8A=D1=87=D0=BA=D0=B0=2C?="
Attachment: "DOC982761717.DOC.zip"
Intelligence
File Origin
# of uploads :
1
# of downloads :
153
Origin country :
n/a
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
7.5/10
Confidence:
100%
Tags:
control.exe keylogger packed replace.exe
Result
Verdict:
MALICIOUS
Link:
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.FormBook
Status:
Malicious
First seen:
2022-02-28 13:30:58 UTC
File Type:
Binary (Archive)
Extracted files:
48
AV detection:
23 of 28 (82.14%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Malicious File
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Dropping
Formbook
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.